The Offshore Loophole: FATF Just Redrew the Crypto Compliance Map
- Elizabeth Travis

- 6 days ago
- 7 min read

When the Financial Action Task Force (FATF) extended its standards to virtual assets in 2019, the assumption was straightforward: bring exchanges inside the regulatory perimeter, and the perimeter would hold. Recommendation 15 (R15) was meant to do for crypto what Recommendation 16 (R16), the travel rule, had long done for wire transfers. Yet almost seven years on, the perimeter has not held. It has simply moved offshore. On 11 March 2026, the FATF published Understanding and Mitigating the Risks of Offshore Virtual Asset Service Providers, and in doing so it named the structural gap that the entire compliance architecture had quietly tolerated. The problem was never the technology. It was the geography.
The offshore VASP is now a defined regulatory subject
For years, the phrase "offshore exchange" was industry shorthand, loose and faintly pejorative. It now carries a precise meaning. The FATF defines an offshore Virtual Asset Service Provider (VASP), or oVASP, as a provider created under the laws of one jurisdiction that actively provides services to clients residing in another, with or without any physical presence in those host markets. The load-bearing word is "actively." An oVASP is not a firm that happens to acquire a few foreign users. It is one that deliberately solicits clients in markets where it holds no licence, onboards them despite local requirements, and routes their transactions through domestic payment infrastructure without authorisation.
This distinction matters because it converts a vague risk into a supervisable category. A firm can no longer claim accidental reach. The FATF's report, drawing on work launched by its Virtual Assets Contact Group in October 2025, sets out the red flags that distinguish active targeting from incidental exposure: the absence of geo-blocking, websites in the host country's language, acceptance of local currency, support for domestic payment methods, and presence in local app stores. These are not technical curiosities. They are evidence of intent, and intent is what supervisors can act upon.
Half the world has left the door open
The most consequential finding in the report is a single figure. According to the FATF, of the 80 jurisdictions that have introduced a VASP licensing or registration requirement, under half, precisely 46 percent, have gone further and adopted an activity-based approach: extending those obligations to a provider according to what it does within a market, regardless of where it was incorporated. The remaining majority apply the core standard, regulating only the firms created or physically located within their borders, which means an offshore provider serving their citizens falls outside the net entirely.
The consequence is not abstract. The FATF identifies the long-standing sunrise issue, the fragmented and staggered way jurisdictions have brought travel rule obligations into force, as a direct enabler of oVASP-related crime. Where an oVASP operates from a jurisdiction that has not implemented the travel rule, its counterparties in compliant markets cannot obtain originator and beneficiary information for cross-border transfers, and competent authorities may lack the legal basis to compel it. The result is a monitoring blind spot, and blind spots are precisely what sophisticated actors are built to find. This is the structural weakness that R15 never resolved. Closing it requires not better technology but a shift in regulatory philosophy, from asking where a firm lives to asking where it operates.
The case studies expose the scale, not the edges
The FATF report is unusual in the specificity of its evidence, and the figures are sobering. In one investment fraud scheme analysed by Nigeria's financial intelligence unit, oVASPs and opaque corporate structures moved illicit proceeds across borders, with victim funds funnelled through layered intermediary wallets on the TRON blockchain. Offshore exchanges served as the final cash-out points. One global VASP-linked wallet held approximately 600 million US dollars at the time of analysis. That is not a loophole at the margin. It is a highway. The same investigation laid the sunrise problem bare: the funds moved into oVASPs in jurisdictions that had not fully applied R16, and investigators could not obtain the originator and beneficiary data they needed.
The named cases are starker still. In February 2025 the Seychelles-based exchange OKX pled guilty in the United States to running an unlicensed money-transmitting business. It had actively served US customers despite a policy that claimed to block them, and agreed to penalties exceeding 504 million US dollars. The report's central study of nested abuse is Binance, inside which the OFAC-designated exchanges Suex and Garantex operated through broker-opened subaccounts, part of a resolution that totalled more than 4.3 billion US dollars. These are not edge cases. They are the largest firms in the sector.
The typologies extend beyond fraud. Indonesia's financial intelligence unit identified virtual asset-based support for terrorist groups in Syria, with financiers using oVASPs including KuCoin and CoinEx to convert between asset types and obscure their trails before moving funds to non-custodial wallets. The report also dwells on a quieter abuse: nested relationships, whereby an unlicensed offshore provider accesses a licensed VASP's services by posing as an ordinary individual customer. Estonia's financial intelligence unit documented exactly this. An unlicensed oVASP onboarded at an Estonian-licensed VASP as a handful of retail individuals, but the accounts traded like algorithms, not people. The email domains even carried the name of an API trading platform. The licensed firm believed it was serving retail clients. It was providing correspondent-style access to an entire unsupervised business.
This is no longer a crypto problem
The instinct of a traditional bank reading an FATF virtual assets report is to file it under "not our concern." That instinct is now indefensible. The report is explicit that the risks generated by oVASPs reach the fiat payment rails and correspondent banking networks that underpin global commerce. Any institution that processes payments for, provides correspondent banking to, or accepts deposits from a virtual asset business is exposed to the oVASP framework, whether or not it touches a single token itself.
The FATF's recommendations to the private sector are correspondingly direct. Firms should assess their group-wide exposure to unlicensed providers, apply consistent controls across every entity in their group, ensure that no group entity is itself operating as an unsupervised oVASP abroad, and decline to establish or maintain relationships with unlicensed counterparties. The third of these deserves particular attention. A multinational group can be both supervisor and offender, running a compliant onshore business while a subsidiary quietly solicits customers in markets where it holds no licence. The report asks firms to look not only outward at their counterparties but inward at their own structure.
Enforcement is moving from monitoring to disruption
The report does more than diagnose. It catalogues what works, and the British example sits near the front. Following the introduction of clear rules for oVASPs promoting services to UK residents, the Financial Conduct Authority (FCA) has issued more than 2,300 alerts on illegal promotions, driven the takedown of more than 1,000 scam websites, sent more than 60 app-removal requests to the Google and Apple stores, and commenced civil litigation against an oVASP for unlawfully promoting to UK consumers. That programme has hardened in parallel, beyond the report's cut-off. In February 2026 the FCA brought its first enforcement proceedings against an offshore platform under the financial promotions regime, and in April 2026 it led its first coordinated crackdown on illegal peer-to-peer trading, raiding eight London premises alongside HM Revenue and Customs.
What unites these actions is a recognition that an offshore firm cannot be raided at its headquarters, so it must be disrupted at the points where it touches the regulated economy. The FATF endorses exactly this logic, recommending that host authorities place obligations on domestic banks, payment service providers, app stores and advertising platforms to identify and cut off non-compliant oVASPs. Japan did precisely that, requesting that Apple and Google remove unregistered offshore apps in early 2025. Where persuasion fails, the principle is the same: cut the fiat on-ramps and off-ramps, and the offshore business loses its domestic revenue.
No regulator sees the whole picture alone
An oVASP exists under one jurisdiction's laws and trades under another's, which means enforcement almost always depends on someone abroad agreeing to look. The report describes how Nigerian supervisors at the Securities and Exchange Commission, when direct channels with offshore regulators were absent or too slow, routed requests through their financial intelligence unit and the Egmont Group's secure platform to obtain beneficial ownership information, confirm investigations, and attach real-world identities to wallets flagged by blockchain analytics. It documents direct collaboration between the Cayman Islands Monetary Authority and Abu Dhabi Global Market's regulator that uncovered governance failures and unlicensed activity, ending in cancelled registration, penalties of 8.85 million US dollars and a ban on the beneficial owner. And it points to domestic plumbing, such as New Zealand's Virtual Assets Investigation Resource Group and India's multi-agency virtual asset sub-group, as what turns scattered intelligence into coherent enforcement.
What firms should reassess now
Verification, not transmission, is the standard that now matters. The practical consequences follow directly. Counterparty due diligence can no longer treat a foreign licence as sufficient comfort; the relevant question is whether a counterparty is licensed for the activity it conducts in the markets it serves. Onboarding controls should screen for the FATF's red-flag indicators, because a counterparty that accepts host-currency deposits and advertises in the local language is signalling its own regulatory status. Group structures demand fresh scrutiny, since the most damaging exposure may be internal. And for any firm relying on travel rule data, the offshore gap is a reminder of a hard truth: an incoming transfer's accompanying information is only as reliable as the weakest link in its chain.
FATF President Elisa de Anda Madrazo framed the stakes plainly, warning that oVASPs create blind spots criminals are clearly exploiting and urging both governments and the private sector to act on the identified good practice. The credibility of the global virtual assets regime now depends not on the standards already written but on whether jurisdictions are willing to extend them to the firms that have built their business models on staying just out of reach.
Conclusion
The offshore VASP is the regime's own shadow, the predictable consequence of building a perimeter and assuming firms would choose to stand inside it. The March 2026 report is significant not because it reveals a new threat but because it refuses to let the gap remain unnamed. For a decade the architecture of virtual asset supervision rested on incorporation. It now rests, or must rest, on activity.
The loophole was never offshore at all. It was the gap between where the rules were written and where the money actually moves, and closing that gap is the work that remains.
Do you know whether your counterparties are licensed for what they do, or only for where they are based?
At OpusDatum, we help firms translate the FATF's oVASP framework into practical control changes, mapping exposure across counterparties, group structures and payment relationships before a supervisor does it for them. Contact us to find out more.


